CyberRota Analysis
AI-GeneratedThe Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress prior to version 7.0.9 is vulnerable due to a lack of capability checks and nonce verification on store-management actions. This flaw allows any authenticated user, including subscribers, to disconnect the store, effectively taking the storefront offline until an administrator intervenes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.